What to include
Explain what happened, why it matters to defenders, when it occurred, and how the information can be verified. Include public source links, affected products or organizations, version information, and a contact method when available.
Use ordinary email carefully
Email is not an anonymous submission channel. Do not send passwords, access tokens, private keys, personal reader data, customer records, malware, or information obtained by accessing a system without authorization. Contact the desk before sending unpublished files that may contain sensitive information.
Send a first message to [email protected]. The desk will confirm whether and how to continue.
Website security reports
A vulnerability in nulltap.sh or the publication pipeline should be reported to [email protected]. Machine-readable reporting details are available at /.well-known/security.txt.
Verification and attribution
Submission does not guarantee coverage. Nulltap may seek corroboration, contact affected organizations, or decline material that cannot be verified safely. Attribution and source-protection expectations should be agreed with the editor before publication.